Agent skill

Secrets

by BuilderIO in BuilderIO/agent-native

Declaratively register API keys and service credentials a template needs so they appear on Settings › API keys and in the onboarding checklist.

No licenceAuto-check: notesBackend & APIs

Install Secrets

skills CLI
$ npx skills add BuilderIO/agent-native --skill secrets -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install BuilderIO/agent-native secrets --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/BuilderIO/agent-native.git skills-src && mkdir -p .claude/skills && cp -r skills-src/community-templates/win-loss-memo/.agents/skills/secrets .claude/skills/secrets && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
secrets
GitHub stars
7.1k
Token cost
~5.1k tokens
SKILL.md length
2,148 words
Files
1
Skills in repo
108
Repo updated
First seen
Licence
None found

At a glance

Declaratively register API keys and service credentials a template needs so they appear on Settings › API keys and in the onboarding checklist.

  • Tasks that involve OAuth and OpenID Connect
  • SKILL.md covers Non-negotiable rule, Google OAuth triage, Credential Modeling Preflight and When to use, plus 10 more sections
  • Calls curl, jq and pnpm; reaches hooks.slack.com and platform.openai.com; needs OPENAI_API_KEY and SECRETS_ENCRYPTION_KEY

What it does

Secrets is an agent skill from BuilderIO/agent-native. Declaratively register API keys and service credentials a template needs so they appear on Settings › API keys and in the onboarding checklist. Use before adding any third-party credential or setup UI so API keys, OAuth connections, and scoped configuration use the correct shared primitive.

Its SKILL.md is about 5.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering OAuth and OpenID Connect. The repository describes itself as: A framework for building agentic apps.

When your agent uses it

  • Tasks that involve OAuth and OpenID Connect

Example prompts

  • “/secrets”

Requirements

  • A credential in OPENAI_API_KEY
  • A credential in GOOGLE_CLIENT_SECRET

What it can do on your machine

Read from SKILL.md and the folder at commit 1c2de07. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl
    • jq
    • pnpm
    • npx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • hooks.slack.com
    • platform.openai.com
    • api.openai.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • OPENAI_API_KEY
    • SECRETS_ENCRYPTION_KEY
    • WORKSPACE_SECRETS_ENCRYPTION_KEY
    • A2A_SECRET
    • GOOGLE_CLIENT_SECRET
    • ANALYTICS_SECRETS_ENCRYPTION_KEY
    • BETTER_AUTH_SECRET
    • API_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Secrets loads about 5.1k tokens when it runs. Until then it costs about 75 tokens; SKILL.md has 2,148 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~75
When it runs · the whole SKILL.md, loaded when a task matches
~5.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:35
    in `.env` or deployment environment variables, and never add a provider-specific

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Without a licence we can't republish the file, so here is its outline and opening line. It has 2,148 words (~5,144 tokens).

“Never hardcode credential values. Source, docs, tests, fixtures, prompts, seed data, and generated extension/app content may mention credential names such as OPENAI_API_KEY, but must not contain real API keys, tokens, webhook URLs, signing secrets, OAuth refresh tokens, or private Builder/customer…”

— opening of SKILL.md by BuilderIO
name
secrets
scope
dev
metadata.internal
true

Read the full SKILL.md on GitHub

Files

Just SKILL.md in community-templates/win-loss-memo/.agents/skills/secrets of BuilderIO/agent-native.

Open the folder on GitHubat commit 1c2de07

Compare with similar skills

Secrets next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Secrets compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Secrets this skillBuilderIO/agent-native7.1k—~5.1kAutomated safety check: NotesNone
Fortify Developmentcoollabsio/coolify63k4 repos~1.9kAutomated safety check: PassMIT
OmniRoute Provider Managementdiegosouzapw/OmniRoute75k—~2.4kAutomated safety check: PassMIT
Antipattern Preventiondoorkeeper-gem/doorkeeper5.5k—~1.1kAutomated safety check: PassMIT
Cognitoitsmostafa/aws-agent-skills1.2k1 repos~2.3kAutomated safety check: PassMIT
Notion Worker Third-Party Auth Guidemakenotion/workers-template4391 repos~3.5kAutomated safety check: NotesMIT

Similar skills

  • Fortify Development

    coollabsio/coolify

    ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.

    63k GitHub starsUsed in 4 repos~1.9k tokens
    Backend & APIsAuto-check passed
  • OmniRoute Provider Management

    diegosouzapw/OmniRoute

    Manages AI provider connections, API keys, OAuth flows and connection tests through OmniRoute's REST API across its 327-provider catalog.

    75k GitHub stars~2.4k tokensUpdated today
    Backend & APIsAuto-check passed
  • Antipattern Prevention

    doorkeeper-gem/doorkeeper

    Avoid common Ruby and Rails antipatterns that degrade maintainability and performance.

    5.5k GitHub stars~1.1k tokensUpdated today
    Backend & APIsAuto-check passed
  • Cognito

    itsmostafa/aws-agent-skills

    AWS Cognito user authentication and authorization service. An agent skill from itsmostafa/aws-agent-skills.

    1.2k GitHub starsUsed in 1 repo~2.3k tokens
    Backend & APIsAuto-check passed
  • Notion Worker Third-Party Auth Guide

    makenotion/workers-template

    Official

    Decides whether a Notion Worker should use a brokered credential, a plaintext environment secret, or OAuth to authenticate against a non-Notion service.

    439 GitHub starsUsed in 1 repo~3.5k tokens
    Backend & APIsAuto-check: notes
  • Stripe Best Practices

    kanchengw/cnllm

    Guides Stripe integration decisions — API selection (Checkout Sessions vs PaymentIntents), Connect platform setup (Accounts v2, controller properties), billing/subscriptions, Treasury financial…

    173 GitHub starsUsed in 2 repos~925 tokens
    Backend & APIsAuto-check passed

More from BuilderIO/agent-native

All 108 skills in this repo
  • Bug Trace

    BuilderIO/agent-native

    Find the root cause of a reported bug: take in the report (GitHub issue, Jira ticket, file, or pasted text), trace the failing path hop by hop with each hop's runtime precondition, find the recent…

    7.1k GitHub stars~555 tokensUpdated today
    Auto-check passed
  • Identify Fragile Systems

    BuilderIO/agent-native

    Nightly refactor review: find the systems the last day's commits hit hardest, use three weeks of history to tell fragile from fast-moving, write a plan per systemic fix, and file deduplicated Jira…

    7.1k GitHub stars~957 tokensUpdated today
    Auto-check passed
  • Jira Refactor Findings

    BuilderIO/agent-native

    File and track refactor findings in Jira without duplicates: match a run against existing refactor-findings tickets, create tickets from plan files (Pod, label, attached plan, run link), record…

    7.1k GitHub stars~779 tokensUpdated today
    Auto-check passed
  • System History

    BuilderIO/agent-native

    Blobless-safe git and PR history for this repo. An agent skill from BuilderIO/agent-native.

    7.1k GitHub stars~727 tokensUpdated today
    Auto-check passed
  • Actions

    BuilderIO/agent-native

    How to create and run agent actions. An agent skill from BuilderIO/agent-native.

    7.1k GitHub stars~4.4k tokensUpdated today
    Auto-check passed
  • Client Methods

    BuilderIO/agent-native

    Client method surface rules. An agent skill from BuilderIO/agent-native.

    7.1k GitHub stars~1.2k tokensUpdated today
    Auto-check passed

Categories

Questions about Secrets

What does Secrets do?

Declaratively register API keys and service credentials a template needs so they appear on Settings › API keys and in the onboarding checklist. Secrets is an agent skill from BuilderIO/agent-native. Declaratively register API keys and service credentials a template needs so they appear on Settings › API keys and in the onboarding checklist.

When should I use Secrets?

Secrets fits situations like: tasks that involve OAuth and OpenID Connect.

How do I install Secrets in Claude Code?

Run `npx skills add BuilderIO/agent-native --skill secrets -a claude-code`. Or copy the skill folder (community-templates/win-loss-memo/.agents/skills/secrets in BuilderIO/agent-native) into .claude/skills/secrets in your project. Claude Code loads it when a task matches its description.

How do I install Secrets in Codex?

Run `npx skills add BuilderIO/agent-native --skill secrets -a codex`. Or copy the skill folder (community-templates/win-loss-memo/.agents/skills/secrets in BuilderIO/agent-native) into .agents/skills/secrets in your project. Codex loads it when a task matches its description.

Can I use Secrets in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add BuilderIO/agent-native --skill secrets -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/secrets, .gemini/skills/secrets, .github/skills/secrets and .opencode/skills/secrets in your project.

What does Secrets need to run?

Going by SKILL.md and its folder, Secrets needs the command-line tools its instructions call (curl, jq, pnpm and npx) and credentials named OPENAI_API_KEY, SECRETS_ENCRYPTION_KEY, WORKSPACE_SECRETS_ENCRYPTION_KEY and A2A_SECRET. Our summary lists: A credential in OPENAI_API_KEY; A credential in GOOGLE_CLIENT_SECRET.

Does Secrets access the network?

SKILL.md names 3 domains. In commands or code: hooks.slack.com, platform.openai.com and api.openai.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Secrets safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Secrets use?

No licence was found for Secrets or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.

How many tokens does Secrets use?

About 5.1k tokens (SKILL.md is roughly 21k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Secrets?

Skills that share tags, products or a category with Secrets: Fortify Development (coollabsio/coolify, 63k stars), OmniRoute Provider Management (diegosouzapw/OmniRoute, 75k stars), Antipattern Prevention (doorkeeper-gem/doorkeeper, 5.5k stars) and Cognito (itsmostafa/aws-agent-skills, 1.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Secrets?

BuilderIO (a GitHub organization) maintains it in BuilderIO/agent-native, which has 7,113 GitHub stars. The repository holds 108 skills in this directory. The repository was last updated on October 10, 2026.

Source: BuilderIO/agent-native on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.